In my earlier post on implementing STIR/SHAKEN, I covered what building signing and verification into a SIP stack involves, including the tricky diversion (div) PASSporT chains. What I didn't cover is how you know the result is correct. If you write both the signer and the verifier, all you've proven is that they agree with each other.
Chris Wendt, a long-time contributor to the STIR/SHAKEN specifications, recently invited me to try the validation tools he's been building at appliedbits.com/library/tools. They give you an independent check on your output, and I wish I'd had them while I was writing my own implementation.
Decoding PASSporTs. Paste in a SHAKEN or div Identity header and the decoder lays out the header, claims and signature information, so you can see exactly what your code produced. You can paste straight from a SIP trace with the "Identity:" prefix still attached. It also checks the token against the spec and reports any problems it finds.
Inspecting certificates. The certificate decoder takes a PEM, or fetches the certificate from the x5u URL, and checks it against the STIR/SHAKEN certificate requirements. It also fetches from loopback addresses, which is handy when you're testing locally. It supports both US and Canadian certificates. The errors it reports include:
Checking div chains. Diversion is where most implementations fall short, and it's the hardest part to verify by eye. The tools validate the whole chain, so you can confirm that SHAKEN → DIV1 → DIV2 → DIVn all link up correctly, and they include an example to work from.
Why it matters. STIR/SHAKEN has a lot of details: attestation levels, certificate profiles, origid formats, chain ordering. It's easy to build something that works against your own code and fails against someone else's. An outside check catches those problems earlier. For developers, that means faster debugging. For operators, it means a way to verify what your systems are actually putting on the wire.
If you work with SHAKEN or div PASSporTs, give the tools a try at appliedbits.com/library/tools.
Example (partial screen shot only):